DRAFT — pending attorney review. An attorney has not reviewed this document yet, and it may change before its final version.
Privacy Policy
Version 0.4.0. In effect since October 3, 2026.
Includes the full and short privacy notices for Mexico (sections 18 and 19). For users in Mexico, the Spanish version of those sections is the official aviso de privacidad.
| Version | 0.4.0 |
| Effective date | October 3, 2026 |
| Controller | Osvaldo Rodriguez (an individual) |
| Address | Dallas, Texas, United States |
| Privacy contact | tripsettled.app@gmail.com |
The short version
- We only ask for what's needed for you to plan trips with your group: your email, your name and what you enter in your trips.
- We don't sell your data or use it for advertising. There are no ads in Tripsettled.
- Your data is stored in Texas, USA, on Microsoft Azure servers; emails you send us stay in Gmail. If you live in Mexico, this means your data leaves the country.
- Nobody in your group sees your email. What you add to a trip is visible to its members according to each item's visibility, and some data is private by default.
- You can download all your data and delete your account from My account at any time. When you delete it, we erase your personal data; backups delete themselves within 7 days at most.
- Sensitive data (health and minors) follows stricter rules and requires your explicit consent.
- You have rights over your data: in Mexico, the ARCO rights; in the US, access, correction, deletion and portability, among others. Write to us at tripsettled.app@gmail.com.
1. Who is responsible for your data
Osvaldo Rodriguez, an individual (not a company) located in Dallas, Texas, United States, is the controller of your personal data in Tripsettled. In this policy, “we” and “us” refer to him. For any privacy matter, including rights requests, write to tripsettled.app@gmail.com. The person who handles those requests is Osvaldo Rodriguez.
2. Who this policy applies to
It applies to the data of:
- people who have a Tripsettled account;
- people we invite to sign up during the test phase who don't have an account yet;
- people without an account whom another member adds to a trip;
- minors whom an adult adds as dependents;
- visitors to the public pages (home, legal documents and invitation previews).
It covers tripsettled.com, its subdomains (including the test version dev.tripsettled.com) and any app we publish later.
3. What data we process
3.1 Your account data
| Data | Why |
|---|---|
| Email address (in lowercase) and whether it's verified | To identify you, let you sign in and send you service emails |
| The name your group sees | To show it to the members of your trips. You choose it when you accept the terms. |
| Preferred language | To show you the app and emails in your language |
| Password, only if you set one | To let you sign in. We never store your password: we store a value derived with the argon2id algorithm, which can't be turned back into the password. |
| Account status (active or deactivated) and internal identifier | To manage the account |
3.2 Data we receive from Google, only if you choose to sign in with Google
Google sends us your Google account identifier, your email, whether Google has verified it, and your name. We keep the identifier to recognize you next time. When we create your account, we use your Google name to prefill the name your group will see; you can change it before you accept the terms, or later in My account. Google may also send your photo and language, but we don't keep them. We never receive your Google password or your contacts.
3.3 Data generated when you use the app
| Data | What it includes |
|---|---|
| Sessions | A session token that we store as a hash; the start, last-activity and expiry dates; and the type of browser and operating system (for example, “Chrome / Android”). We don't store your IP address or your browser's full description. |
| Sign-in links | Single-use tokens to sign in with a magic link or verify your email: the token's hash, what it's for, the email it was sent to, the email's language, and when it expires (15 minutes). For magic links, also the app page you'll return to after signing in. For verification links, the hash of a value that ties the link to the browser you signed up in. |
| Google sign-in in progress | Temporary technical values that protect sign-in with Google (they last 10 minutes). |
| Document acceptance | Which document you accepted, its version, the language you read it in, the date and time, and your confirmation that you are 18 or older. |
| Consents | Which consents you gave or withdrew (email notifications, sending documents to AI, health data), when, and their history. |
| Access list | During the test phase, the emails of the people we invite to sign up, with an optional internal note on why we invited them (for example, “Lupe's friend, Oaxaca trip”). The note never contains sensitive data. See section 3.7. |
| Abuse protection | Counters of attempts (password sign-ins, link requests and sign-ups) in 15-minute or one-day windows, per IP address (or per network, if you use IPv6), per account or per email. For example, we limit password attempts per account and send at most 10 sign-in emails a day to the same address. Each counter is identified by a value we compute with a cryptographic function and a secret key (HMAC-SHA-256). These counters don't store the IP or the email, and they can't be worked out without the key. |
| Audit log | Which important action was taken (for example, creating the account, signing in, accepting documents, correcting your profile, changing a consent, exporting your data, deleting the account, or a change made by the administrator), who took it and when, with internal identifiers only. |
| Technical logs | Request ID, operation, result, duration and error type. They may include internal identifiers, but not your name, your email or what you write. |
| Telemetry | Server performance and error data. Microsoft derives an approximate location (city, state, country) from the IP and then discards the IP. |
| Emails we send you | Your address and the content of the email, which Microsoft processes to deliver it. Our emails have no tracking pixels or tracked links. |
3.4 Your trip data
Some of these features arrive in upcoming versions of the app. When they are available, we will process:
- About the trip: name, type, dates, stops and destinations, daily plan, activities, meals, estimated costs, links and confirmation codes.
- About each member: their role, when they arrive and leave, when they're unavailable (the reason is optional and private), which activities they join, where they sleep, which car they ride in and, if they enter them, their travel preferences.
- Lodging and transportation: rooms, beds and who sleeps where; cars, seats and car seats; the address of a member's home, if the group stays there; and lodging access codes.
- Expenses and budget: who paid for what, how it's split, payments between members and balances; personal budget caps, which are private.
- Documents you import with AI, when that feature exists and only with your consent (see the AI Use Policy).
- Feedback you send us from the app.
Other people's data. You can add adults without an account to a trip (name or nickname and the data needed to plan) and minors as dependents (only name or nickname and whether they need a car seat). If you add someone, we process their data under this policy; that person can exercise their rights as explained in section 10.8.
3.5 Sensitive data and data we handle with extra care
- Health-related dietary restrictions (allergies and intolerances): these are sensitive data. We only store them with your explicit consent (or that of your responsible adult, if you're a minor). We use them only to plan meals, and only you and the people who need them, such as whoever is cooking, can see them.
- Minors' data: only the minimum described in section 3.4, added by their responsible adult.
- Lodging access codes: stored encrypted and visible only to the people staying there.
- Sign-in credentials: your email together with your password (stored only as a hash) and sign-in tokens (also stored as hashes).
3.6 What we don't collect
We don't ask for your precise location, your contacts, your photo, card details, passport numbers or government IDs. If you import a confirmation that contains them, we remove them before storing it. We don't use tracking technologies for advertising.
3.7 If we invited you and you don't have an account yet
During the test phase, only invited people can create an account. If you asked or agreed to be invited, we keep your email on the access list, sometimes with an internal note on why we invited you. We only use it to let you create your account; we don't send you anything until you ask to sign in.
- We show you this policy on the sign-in screen, before your account is created.
- Your email stays on the list until you delete your account or we remove it. If you start signing up and don't finish, we delete that sign-up after 7 days, but your email stays on the list so you can try again.
- You can ask us at any time to remove you from the list, or to see what data we hold, by writing to tripsettled.app@gmail.com.
4. How we use your data
4.1 Uses needed to provide the service
- Create and manage your account and verify your email.
- Let you sign in and keep your session secure.
- Send you service emails: sign-in links, verification, security notices and the notice that your account was deleted.
- Let you plan trips with your group and show each member what they're meant to see.
- Record which documents you accepted and which consents you gave.
- Protect the service and its users: usage limits, fraud and abuse prevention, security incident investigation and the audit log.
- Handle your rights and support requests.
- Operate, back up and maintain the service: technical logs, backups and bug fixes.
- Comply with legal obligations and defend our rights.
4.2 Uses that require your consent
These aren't needed to provide the service. You can say no or withdraw your consent at any time, and the rest of the app keeps working:
- Email notifications and reminders about your trips, when available.
- Sending documents to an AI provider to import bookings, when that feature exists.
- Storing health-related dietary restrictions.
- Product analytics to understand how the app is used. They don't exist today; if we add them, they will only run if you accept them in the cookie notice.
4.3 What we don't do
- We don't sell your personal data.
- We don't share it for targeted advertising or for advertising based on your activity on other sites.
- We don't make automated decisions that produce legal or similarly significant effects on you.
- We don't use your data to train AI models, and neither does our AI provider (see the AI Use Policy).
5. Legal grounds for using your data
| Use | United States | Mexico |
|---|---|---|
| Uses needed for the service (4.1) | Needed to provide the service you asked for, disclosed in this policy | Needed to fulfill our legal relationship with you (art. 9, sec. IV of the law) and your consent when you accept this policy |
| Notifications, AI and analytics (4.2) | Your consent | Your express consent, which you can revoke (art. 7) |
| Health-related dietary restrictions | Your consent, as Texas law requires for sensitive data | Your express written consent, given with your account as the authentication mechanism (art. 8) |
| Expenses and payments between members, when available | Needed to provide the service | Needed for the legal relationship (arts. 7 and 9, sec. IV) and your express consent when you accept this policy |
| Security, audit and legal compliance | Needed to protect the service and comply with the law | Arts. 9, secs. I and IV |
| Access list (invited people without an account) | Needed to give you the access you asked for or agreed to | Your consent, when you ask for or agree to the invitation, with this policy available to you on the sign-in screen (art. 7) |
In this table, “the law” is Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares), published in the Diario Oficial de la Federación on March 20, 2025.
6. Who sees your data inside Tripsettled
- The members of your trips see your name and what you add to each trip, according to each item's visibility (the whole group, only you, or only the people involved). They never see your email.
- Someone who receives an invitation link and doesn't have an account yet only sees the trip summary chosen by the organizers, with no personal data about the members.
- The person who operates the service only accesses account data when needed (support, security or legal compliance), and every access is recorded in the audit log.
- Nobody else.
7. Who we share your data with
- Providers that process data on our behalf (processors). Microsoft hosts the app, the database and files, sends emails and receives technical logs. It may only use your data to provide that service to us, under a data protection agreement. The full list is in the Subprocessors document.
- Google, only if you choose to sign in with Google. Google confirms your identity and sends us the data in section 3.2. We don't send Google anything about your trips. Google handles your Google account data under its own privacy policy.
- Google (Gmail), if you email us. Our privacy email, tripsettled.app@gmail.com, is a Gmail account. Google stores the messages you send us and our replies under its own terms and privacy policy; for this service it doesn't act as our processor. If you'd rather not email us, you can exercise most of your rights from My account.
- Authorities, only when the law requires it (for example, a court order) or to defend rights in legal proceedings.
- If the service changes hands, for example through a sale or reorganization, we will tell you in advance, and whoever receives it must respect this policy. You will be able to delete your account if you don't agree.
We don't share your data with any other third parties. Today we don't make any data transfers that require your consent; if we ever need to, we will ask you first.
8. Where your data is stored and international transfers
Your data is stored on Microsoft Azure servers in the South Central US region, in Texas, United States. Emails are processed with Azure Communication Services in the United States. To deliver the service, some Microsoft components may process data in transit outside that region.
If you live in Mexico: your data leaves the country. We send it to Microsoft as our processor (encargado), which handles it only on our behalf and under a contract that requires it to protect your data. Under Mexican law (art. 2, sec. XX), sending data to a processor is not a transfer, but we're telling you so you know. If you choose to sign in with Google, Google handles your Google account data on its own servers, in several countries. The same goes for the emails you send us, which stay in our Gmail account.
9. How long we keep your data
| Data | How long |
|---|---|
| Account, Google link, acceptances and consents | While you have an account. When you confirm your account deletion, they are erased immediately. |
| Accounts whose sign-up isn't completed (email not verified or terms not accepted) | Deleted after 7 days |
| Account of someone who says they are under 18 | Deleted immediately |
| Access list | Until you delete your account or we remove you from the list. Not deleted with incomplete sign-ups. |
| Sessions | While active; deleted 30 days after they end or expire |
| Sign-in links and temporary Google sign-in data | Links are valid for 15 minutes and Google sign-in data for 10. They are deleted no later than 24 hours after they are used or expire. |
| Abuse protection counters | 24 hours |
| Audit log | 12 months; 24 months for records of rights requests. After you delete your account, only with your internal identifier, without your name or email. |
| Technical logs | 30 days |
| Telemetry | 30 days, without your name, email or IP |
| Emails you send us and our replies | 12 months after they're resolved; 24 months for rights requests |
| Backups | Up to 7 days |
An automatic cleanup runs once a day and deletes each item once its period is over, so deletion can take up to one extra day. The details, including what happens to what you contributed to shared trips, are in the Retention and Deletion Policy.
10. Your rights and how to use them
10.1 In the app
In My account you can, without writing to us:
- see and correct your name and language;
- download all your data as a JSON file (access and portability);
- delete your account (cancellation). To confirm, you type your email; if you signed in more than 10 minutes ago, we will ask you to sign in again. We will email you when the deletion is complete;
- give or withdraw your consents;
- sign out of your sessions on other devices.
10.2 By email
Write to tripsettled.app@gmail.com to exercise any right, including the ones not available in the app, or to appeal a decision. Include:
- your name and your account email, or how to reach you;
- which right you want to exercise and which data it concerns (not needed for access requests);
- for a correction, what needs to change and, if applicable, something that supports it;
- anything that helps us find your information.
Our email is a Gmail account, so Google stores what you send us (section 7). Don't attach government IDs or other documents unless we ask for them.
10.3 How we verify your identity
If you make the request from the app while signed in, you're already verified. If you write to us, we will ask you to confirm the request from your account email. Only if that isn't possible will we ask for another way to verify your identity, and only for the information strictly needed. If you act on behalf of someone else (legal representative or authorized agent), we will need a document that proves the authorization.
10.4 Deadlines and cost
- Mexico: we respond within 20 business days of receiving your request. If it's granted, we carry it out within the following 15 business days. If the case justifies it, we may extend each deadline once by the same period, and we will tell you (art. 31).
- United States: we respond and comply within 45 calendar days. If needed, we may extend that once by 45 more days, and we will tell you.
- It's free.
10.5 If you live in the United States
Under your state's law (for example, the Texas Data Privacy and Security Act or the California Consumer Privacy Act), you can:
- confirm whether we process your data and access it;
- correct inaccurate data;
- delete your data;
- get a portable copy of your data;
- opt out of the sale of your data, targeted advertising, and profiling with legal or similarly significant effects. We don't do any of these things;
- limit the use of your sensitive data. We only use it for the purpose you gave it to us for;
- not be discriminated against for exercising your rights;
- act through an authorized agent.
Appeals. If we deny your request, you can appeal by writing “Appeal” to tripsettled.app@gmail.com within 60 days of our response. We will reply in writing within 60 days. If we confirm the denial, you can file a complaint with the Texas Attorney General (https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint) or, if you live in California, with the California Privacy Protection Agency (https://cppa.ca.gov/).
Categories of data in the last 12 months (using California's categories):
| Category | Examples | Source | Purpose | Disclosed to | Sold or shared for advertising? |
|---|---|---|---|---|---|
| Identifiers | Email, internal identifier, Google identifier | You; Google | Uses 1 to 9 in section 4.1 | Service providers (Microsoft) | No |
| Personal records | Name | You; Google | Uses 1 to 4 | Service providers | No |
| Internet activity | Sessions, browser and system type, technical logs | Your browser | Uses 2, 6 and 8 | Service providers | No |
| Approximate location | City, state or country derived from the IP in telemetry | Your connection | Use 8 | Service providers | No |
| Sensitive personal information | Email with password (as a hash) | You | Use 2 | Service providers | No |
10.6 If you live in Mexico: ARCO rights
You have the right to:
- Access: know what data we hold about you and how we process it.
- Rectification: correct inaccurate, incomplete or outdated data.
- Cancellation: ask us to delete your data. We will tell you when we're done.
- Opposition: ask us to stop processing your data for a legitimate reason, or when automated processing significantly affects you.
You can exercise them in the app (10.1) or by email (10.2). We will reply through the same channel you used. We can only refuse in the cases the law provides, for example if your identity isn't verified, if we don't hold the data, or if a law requires us to keep it, and we will always explain why.
If you disagree with our response, or if we don't respond in time, you can file a data protection request (solicitud de protección de datos) with the Secretaría Anticorrupción y Buen Gobierno within 15 business days of our response or of the response deadline (art. 40).
10.7 Withdrawing your consent and limiting the use of your data
- Withdraw any consent from My account or by writing to us. Withdrawing doesn't affect what we did before with your consent, but it may stop the related feature from working (for example, AI import).
- Control who sees each item with the app's visibility options. Some data is private by default.
- To limit any other use or disclosure, write to tripsettled.app@gmail.com.
10.8 People without an account and minors
- If someone added you to a trip and you don't have an account, you can write to us to access, correct or delete your data. We will ask only for what we need to confirm it's you.
- If you're on the access list and don't have an account, you can ask us the same, including to remove you from the list.
- A dependent minor's rights are exercised by their responsible adult in the app, or by either parent or guardian by writing to us.
11. Minors
Tripsettled is not directed at people under 18 and we don't allow them to have accounts. We don't knowingly collect data directly from minors. A minor only appears in the app as a dependent of a responsible adult, with their name or nickname and whether they need a car seat; their dietary restrictions are stored only with that adult's consent. If someone says they are under 18 when accepting the terms, we delete their account immediately. If we learn in any other way that an account belongs to a minor, we close it and delete its data.
12. Security
We protect your data with administrative, technical and physical measures, including:
- encrypted connections (HTTPS) and data encrypted at rest in Azure;
- passwords and tokens stored only as hashes, and lodging access codes encrypted field by field;
- database access with no stored passwords, using Azure managed identities and least privilege;
- technical logs without names, emails or what you write;
- an audit log of administrator access to user data;
- limits on sign-in attempts;
- backups kept for 7 days at most.
No system is 100% secure. If a security breach significantly affects your rights, we will tell you right away and explain what to do, as the applicable laws require.
13. Cookies
Today we only use strictly necessary cookies: your session cookie, two temporary ones that protect signing in with Google and signing up with a password, and one that remembers your cookie choice. We don't use advertising or analytics cookies. The details are in the Cookie Policy.
14. Artificial intelligence
Today no feature uses AI and we don't send data to any AI provider. When that changes, we will ask for your consent before sending your documents. The details are in the AI Use Policy.
15. Opt-out signals (Global Privacy Control)
We don't sell your data or share it for advertising, so there's nothing to opt out of. If we add analytics in the future, we will treat your browser's Global Privacy Control signal as a refusal of analytics.
16. Changes to this policy
- We will publish each new version in the app's Legal section, with its number and effective date.
- Important changes, such as new uses of your data, new types of data or new types of recipients: we will tell you by email and in the app before they apply, and ask you to accept them before you keep using the app. In the meantime, you will be able to read the documents, export your data or delete your account.
- Minor changes, such as corrections or clarifications, apply as soon as they are published.
17. Contact and authorities
- Us: tripsettled.app@gmail.com.
- Mexico: Secretaría Anticorrupción y Buen Gobierno (https://www.gob.mx/buengobierno), the authority for personal data held by private parties.
- Texas: Texas Attorney General (https://www.texasattorneygeneral.gov/).
- California: California Privacy Protection Agency (https://cppa.ca.gov/).
18. Full privacy notice for Mexico (aviso de privacidad integral)
This notice follows article 15 of Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (DOF March 20, 2025). The sections above give the details.
I. Identity and address of the controller. Osvaldo Rodriguez, an individual, located in Dallas, Texas, United States. Contact: tripsettled.app@gmail.com. The person designated to handle data subjects' requests is Osvaldo Rodriguez.
II. Personal data we process.
- Identification and contact: email, name, language, Google identifier if you choose to sign in with Google.
- Authentication: password (only as a hash), sessions with browser and operating system type, sign-in tokens (as hashes).
- Service records: document acceptance and age confirmation, consents, audit log, abuse counters derived from the IP or email, technical logs.
- Access list: the email of people invited to sign up and an optional internal note, without sensitive data.
- Trip data, as features become available: dates, presence and availability, participation, lodging and transportation, a home address if the group stays there, access codes, preferences, expenses and payments between members (financial data), and budgets.
- About third parties you add: adults without an account and dependent minors (name or nickname and the data needed to plan the trip).
- Sensitive data: health-related dietary restrictions. Only with your express written consent, given with your account as the authentication mechanism.
III. Purposes.
- Needed for our relationship with you: the nine listed in section 4.1.
- Require your consent and aren't needed: email notifications and reminders, sending documents to an AI provider, storing health-related dietary restrictions, and product analytics. You can say no from My account or by writing to us, without affecting the needed purposes.
IV. Options and means to limit the use or disclosure of your data. The consents in My account, the visibility options for each item in your trips, and the email tripsettled.app@gmail.com.
V. How to exercise ARCO rights. From My account (download your data, correct your profile, delete your account) or by email to tripsettled.app@gmail.com, with the information in section 10.2. We respond within 20 business days and, if granted, carry it out within the following 15 business days. It's free. If you're not satisfied, you can go to the Secretaría Anticorrupción y Buen Gobierno (section 10.6).
VI. Withdrawing consent. From My account or by email to tripsettled.app@gmail.com, with no retroactive effect (section 10.7).
VII. Processors and transfers. We send your data to Microsoft Corporation, our processor, which hosts and processes it in the United States. If you email us, your messages stay in our Gmail account, which Google LLC runs under its own terms. We don't make transfers that require your consent. We would only disclose data to authorities in the cases in article 36 of the law (for example, when legally required or to defend a right in court). If we ever wanted to make a transfer that does require your consent, we would ask you first.
VIII. Cookies and similar technologies. We only use strictly necessary cookies: session, protection of sign-in with Google, protection of password sign-up, and a record of your cookie choice. We don't use them to collect data for advertising. You can delete them in your browser, but then you won't be able to stay signed in. Details in the Cookie Policy.
IX. Changes to the notice. We will publish every change in the app's Legal section with its version and date. We will notify you of important changes by email and in the app, and ask you to accept them (section 16).
19. Short privacy notice for Mexico (aviso de privacidad simplificado)
Osvaldo Rodriguez, an individual located in Dallas, Texas, United States, is responsible for your personal data in Tripsettled. We use your email, your name and what you enter in your trips to create and protect your account, let you plan trips with your group, and comply with the law. With your consent, which you can refuse or withdraw at any time, we also use them to send you email notifications and, when those features exist, to process documents with AI and to store health-related dietary restrictions, which are sensitive data. You can limit the use of your data from My account or by writing to tripsettled.app@gmail.com. Your data is stored in the United States. Read the full privacy notice in this app's Legal section.
Change history
| Version | Date | Change |
|---|---|---|
| 0.4.0 | 2026-10-03 | Before taking effect: the controller (Osvaldo Rodriguez, an individual, Dallas, Texas) and the privacy email, which is a Gmail account (sections 7, 8, 9 and 10.2). What you accept doesn't change. |
| 0.3.0 | 2026-10-03 | New cookie that protects password sign-up; more detail on sign-in links (return page, browser binding) and on attempt and email limits; the automatic cleanup runs once a day. What you accept doesn't change. |
| 0.2.0 | 2026-10-03 | Before taking effect: explains the access list for invited people (section 3.7), the name prefilled from Google, immediate deletion when someone says they are under 18, how account deletion is confirmed, the secret key behind the abuse counters, and emails without tracking. Technical logs and telemetry: 30 days. What you accept doesn't change. |
| 0.1.0 | 2026-10-03 | First draft. |